Re: Renewing certificates and public key tokens

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: William Stacey [MVP] (staceywREMOVE_at_mvps.org)
Date: 03/01/05


Date: Tue, 1 Mar 2005 00:26:27 -0500

Why are you using certificates for the SN? Why not just create a .snk and use that? Then you don't have to worry about expire and can use same public key for all versions.

-- 
William Stacey, MVP
http://mvp.support.microsoft.com
  
  "Mike Schilling" <mscottschilling@hotmail.com> wrote in message news:eLEaWMfHFHA.3844@TK2MSFTNGP14.phx.gbl...
  The certificate we use to sign our assemblies was about to expire, so I contacted Verisign to renew it.  The new certificate came, we installed it, we pointed out nightly build at it, the new DLLs got signed, so far so good.  The problem is that, when we looked at the with ILDASM, we noticed that the public keys tokens are different from the ones generated by the older certificate. 
  This is a compatibility problem, of course.  It's not possible to issue a bindingRedirect from a version signed with the older certificate to one signed with the new one, since .NET considers them different assemblies, not two versions of the same assembly.  Verisign insists that renewed certificates always have different public keys, and this is just how things work, but I can't picture that an unavoidable incompatibility is created every year when certificates expire.  What am I (or are they) missing?


Relevant Pages

  • Re: Untrusted certificates with Friendly Name of "Fraudlent, NOT Microsoft"?
    ... The certificates *are* revoked. ... > find it helpful when I have many Thawte freemail certs. ... >>> Expiration just means it is old and all certificates expire. ... >>> certificate and perform a revoke check (by downloading the latest ...
    (microsoft.public.security)
  • Re: Certificates Expired
    ... > What gets me is the constant re-installation of expired certificates. ... > "George Hester" wrote in message ... > One in particular the Microsoft Root Authority has or will expire very shortly. ...
    (microsoft.public.win2000.general)
  • Re: Certificates Expired
    ... What gets me is the constant re-installation of expired certificates. ... One in particular the Microsoft Root Authority has or will expire very shortly. ...
    (microsoft.public.win2000.general)
  • Re: I ask your opinion
    ... Earlier this year we gave 5 gift certificates to a charitable ... enough weekends between now and the time they expire. ... place to stay during a motorcycle tour, ... Iwould definitely have an honest discussion with that charity. ...
    (rec.motorcycles)
  • CA Client Certificates only expire in one years time
    ... I've set up the CA to expire in five years time ... I'd like these certificates to expire in two years time. ... restarted the cert service and it works fine. ... expiry period on the generated client certs to March 2008. ...
    (microsoft.public.windows.server.general)